HNHacker News
TopNewBestAskShowJobs

ewillbefull

1,227 karma · joined March 23, 2012

submissionscomments
ewillbefull··on ZCash Will Be a Truly Anonymous Blockchain-Based Currency
> ZCash's blockchain is a black box and requires you to not only trust them with your anonymity

You do not trust anyone with your privacy in our system. Assuming you're talking about our zk-SNARK parameters, if they were not securely generated you still could not violate anyone's privacy.

ewillbefull··on Critical Update on DAO Vulnerability
The stolen coins are unspendable for the time being due to the design of the contract.
ewillbefull··on Why Rust for Low-Level Linux Programming?
Can you give some examples?
ewillbefull··on Zero-Knowledge Contingent Payment
I think the tooling will improve significantly this year and you should see people able to build protocols with zkSNARKs soon -- without spending days figuring out how everything works.

Ahmed Kosba has been working on jSnark (https://github.com/akosba/jsnark).

I'm building something in Rust called bellman (https://github.com/ebfull/bellman) which should make it easier to construct circuits safely and build these proofs easier, but it's in its early stages.

ewillbefull··on Zero-Knowledge Contingent Payment
Thanks! In this case, the Zcash team did build the first zero-knowledge contingent payment, but we performed it on the Bitcoin network.
ewillbefull··on Zero-Knowledge Contingent Payment
The simple explanation -- which I unfortunately left out of my slides but did elaborate on during my talk -- is that Bitcoin has a way for you to send money to someone contingent on them producing the preimage of a SHA256 hash. The remainder of the script allows you to get your money back if the person doesn't have or doesn't provide the preimage within a certain amount of time.

If you use a zero-knowledge proof to enforce that the preimage of the hash is a key which unlocks some data you want, this becomes a powerful tool for building exotic protocols or performing risky transactions. It also doesn't cost much on the Bitcoin side of things.

ewillbefull··on Zero-Knowledge Contingent Payment
In this particular ZKCP case we use zk-SNARKs because they're fast and they exist, but theoretically we do not need their "non-interactivity" properties.
ewillbefull··on Zero-Knowledge Contingent Payment
Additionally, lightning actually uses the HTLC (Hashed Timelock Contract) transaction style that is used by ZKCPs. I believe it is used to extend lightning channels to multiple hops.
ewillbefull··on Apple fans are coming to hate Apple software
I haven't used Apple software in a long time, but Google is not immune to this either apparently. If you use the YouTube app, and especially if you use Chromecast, you'll experience countless bugs as it fails to reconcile state changes between the devices or properly buffer videos. I'm considering setting up a raspi or something and installing an ad blocker on it to replace my Chromecast. I don't think this is what Google wants but its product is difficult to use any other way.

Hangouts / Google Calendar are also really clunky and seem poorly tested. Things often go out of sync or you're randomly asked to re-login several times a month, and only during video chats.

ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
One of the most important properties of Zcash is "selective disclosure." Effectively, you can audit and perform proofs-of-solvency with the same security as in other cryptocurrencies.

But yes, if someone on the inside "steals" the money, nobody will figure out where it went.

ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
This video should give you a better idea of how anonymous Bitcoin is.

https://www.youtube.com/watch?v=AypRF9q0llU

There are also several startups dedicated to performing Bitcoin blockchain analysis for this specific purpose.

ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
Virtually everyone involved in Bitcoin's development is also well-known and presumably "coerceable." The company makes no difference as far as I can see.
ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
> Or does the 'spend' merely provide a zero knowledge proof that the funding was legitimate?

This. :) (Alongside a demonstration that it wasn't spent before.)

ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
The actual setup of the parameters hasn't occured and will use a much more secure construction which isn't complete yet. The software is still in alpha.
ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
Zcash is planning to use a new multi-party trusted setup scheme that allows a group to securely compute the mathematical structures necessary to protect the zero-knowledge proof integrity.

(Secure Sampling of Public Parameters for Succinct Zero Knowledge Proofs, Ben-Sasson, E. ; Chiesa, A. ; Green, M. ; Tromer, E. et al.)

Only if every member of this group were compromised or dishonest will the setup fail. That is, only 1/N participants need to be honest.

ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
"Buckets" contain cryptographic trapdoors which are necessary to witness spendable value. The sender constructs them and encrypts them with an IND-CCA2-secure key and places it inside the transaction. Only the recipient should be able to decrypt it to obtain the trapdoors which it needs in order to spend it.
ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
Buckets are basically Coins from the original paper. It was changed because a `Coin` implies things that it actually isn't, but bucket is an even worse name, so it'll probably either be called Coin again or perhaps "pour output" or something.
ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
Monero and other ring signature schemes can only feasibly "mix" your transactions with a small number of previous transaction outputs, opening the door to statistical attacks.

Zcash mixes your transaction with every previous transaction. In fact, it goes to great lengths to make transactions indistinguishable from each other.

ewillbefull··on Zcash, an untraceable Bitcoin alternative, launches in alpha
I don't understand this complaint. If the company that is launched fails or is attacked, the currency and the code can live on without it. Its development probably wouldn't be as well-financed but that's about it.
ewillbefull··on Introducing the Shift Card: Use Bitcoin where Visa is accepted
That's a dumb, deliberate misreading of my comment and a ridiculous jump to conclusions. I have done nothing illegal.

I said clearly that I made _one_ transaction (a wire transfer) and I said clearly that they questioned me on my income. Their concern is "where did you get your money" to which I answered them thoroughly.

ewillbefull··on Introducing the Shift Card: Use Bitcoin where Visa is accepted
Same here. I've been through the KYC loops and I know how invasive they have to be occasionally. Coinbase took it to another level.
ewillbefull··on Introducing the Shift Card: Use Bitcoin where Visa is accepted
No, I didn't conduct any illegal transactions. I thought that would be obvious from my second comment. Somehow you believe I would waste my time complaining about Coinbase yet be at clear and obvious fault?
ewillbefull··on Introducing the Shift Card: Use Bitcoin where Visa is accepted
They only appear to care about the customer experience when someone complains on social media, until then they have a history of being jerks to their users.

They closed my account after I made a (relatively small) wire transfer after not using their service for a while. The year before I made much larger transfers that didn't seem to concern them. Suddenly I needed to provide them with lots of financial information.

The law sucks and I don't blame them for this. But I have provided them with more than enough information to prove all of my income is legitimate, including years of tax forms regarding the income and other crap they absolutely did not need to look at.

What bugs me is that they continued to ask me for this information, which took time for me to compile for them, and they ignored me anyway after I provided everything.

Another thing that bugs me is that (they claim) their support desk software is the most secure method of sending them sensitive documents. Ridiculous. The icing on the cake will be when their system is hacked and I lose a lot of important documents that I was under the impression they would be removing, but clearly haven't.

ewillbefull··on Introducing the Shift Card: Use Bitcoin where Visa is accepted
You can now use Bitcoin anywhere VISA is accepted, so long as coinbase doesn't close your account, ignore you and close all the tickets you open. Even if you painstakingly collect and compile sensitive documents for them to review, which was a gigantic waste of my time, thanks!

I have for months encouraged everyone I know not to use coinbase and will continue to do so.

ewillbefull··on Zerocoin startup revives the dream of truly anonymous money
The way you phrase it makes it seem like the parties involved are perpetually at risk of being compromised, as though they must retain and store the secrets necessary for parameter generation forever. When in fact it will be done once, and well in advance of any significant value in the currency which would incentivize crazy government yatta yatta.
ewillbefull··on Zerocoin startup revives the dream of truly anonymous money
Selective disclosure means you decide who can see your transaction information (value, recipients, etc.) and that it's not publicly knowable by default.
ewillbefull··on Classeur.io: Re-enjoy writing, with Markdown
Just used the interface... wow I love it. I need something exactly like this.
ewillbefull··on New Chromecast 2015
Yes, god yes I have. Chromecast used to work just fine last year, but this year it's been a disaster.

* Almost all youtube videos start playing before they're buffered, the video is paused but the audio continues playing until the video resumes and it catches up. Makes watching any 15 second video impossible. The buffering in general is really broken.

* Chromecast loves to play previous videos I watched when I start playing new ones. I frequently have to disconnect youtube from it and start a new session to get it to behave intuitively.

I pretty much have to transcode all of my media to h264/aac in order for it to play on the Chromecast from my computer -- I thought this would get better over time but it hasn't.

ewillbefull··on Disable Windows 10 Tracking
There's no shortage of choice for desktop environments on Linux. If you're looking for a system that's completely user-friendly from the top down, look at Elementary OS. I personally use KDE on Debian, Gnome on Arch, etc. and I haven't had any problems making them usable desktops.
ewillbefull··on Announcing Rust 1.2
Will the MIR/HIR stuff also help with adding features? I'm thinking of things like non-lexical scoping/SEME regions/etc. which might be easier to implement with it.
← PreviousPage 2 of 9Next →